Author Topic: http://disorderstatus.ru/order.php Process: C:\Windows\Sys32\msiexec.exe  (Read 3665 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Hi I've run Zoek but I am still getting a warning message. My problem is stated as follows:
URL: http://disorderstatus.ru/order.php
Infection: URL:Mal
Process: C:\Windows\Sys32\msiexec.exe

Log file exceeds characters allowed, is it oK to post in 2 parts?

Much obliged if you can help out.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Monitoring...
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
As requested, my initial files...

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Multiple Resident Protection warning!

Always have one (and no more than one!) AntiVirus program! In this case having more of them will not provide you with better protection - instead they may cause slowness, lock-ups and even mark another ones as harmful, leading to leave your system unstable and even damaged. Please choose only one from the listed below to stay with and uninstall the others:
  • Microsoft Security Essentials
  • avast! Antivirus

Uninstallation procedure:
  • Press the + R on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for each uninstalled entry, right-click it and select Uninstall.
This should be done until any other steps will be taken.



Fix with Farbar Recovery Scan Tool

This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Sorry but I can'y find MS Security essentials in list of programs

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Skip it then.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Unable to open script file is the response I get.
I did move into a folder the FARBER recovery scan tool and the FRST and fixlist.
Initially, even though all 3 were on my desktop, FARBER would only update and close, so I moved all 3 into 1 folder.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Did script error happen after updating FRST or before?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
After updating. But, not to worry, I downloaded Farber again directly into folder containing fixlist and FRST txt files.
It updated, and then performed script. However, I did get a pop up message for plugin container error. I cancelled it and it warned it would be closing but FARBER continued anyway. Once it finished, it rebooted.
I am attaching file requested.

REDACTED

  • Guest
Re: http://disorderstatus.ru/order.php Process: C:\Windows\Sys32\msiexec.exe
« Reply #10 on: August 05, 2015, 11:52:08 AM »
I see that in the fixlog file there is a portion in Spanish. The translation is as follows:
=========  bitsadmin /reset /allusers =========

"bitsadmin" not recognized as an internal or external command, program or file for batch processing

REDACTED

  • Guest
Re: http://disorderstatus.ru/order.php Process: C:\Windows\Sys32\msiexec.exe
« Reply #11 on: August 05, 2015, 12:07:45 PM »
Seems like there are no more pop up messages.

FYI: Before contacting you I had used GLARY Utilities to review/disable apps in startup menu. I found one that was titled: 842779258
But the PATH WAS   C:\Documents and Settings\All Users\mszdkn.exe
 I was unable to disable it using GLARY UTILITIES, so I searched in regedit under 842779258 and I was unable to modify it or delete it, so I came to you.
Now I see it shows up in the fixlog. So, is this the culprit?

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: http://disorderstatus.ru/order.php Process: C:\Windows\Sys32\msiexec.exe
« Reply #12 on: August 05, 2015, 12:27:03 PM »
Yes, I put it in Fixlog for removal.

Is everything fine now?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: http://disorderstatus.ru/order.php Process: C:\Windows\Sys32\msiexec.exe
« Reply #13 on: August 05, 2015, 12:52:22 PM »
Seems to be. I am most grateful for your help.
I've downloaded McShield to check my USB before reinserting into desktop.

Thanks again.